Summer Certification Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Free Practice Questions for the Symantec Data Loss Prevention 250-587 Exam (2026 Updated)

At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the Symantec 250-587 exam. To support your certification journey, we have made a selection of our premium 2026 Data Loss Prevention practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.

Questions 4

A DLP administrator has enabled and successfully tested custom attribute lookups for incident data based on the Active Directory LDAP plugin. The Chief Information Security Officer (CISO) has attempted to generate a User Risk Summary report, but the report is empty. The DLP administrator confirms the Cisco’s role has the “User Reporting” privilege enabled, but User Risk reporting is still not working.

What is the probable reason that the User Risk Summary report is blank?

Options:

A.

Only DLP administrators are permitted to access and view data for high risk users.

B.

The Enforce server has insufficient permissions for importing user attributes.

C.

User attribute data must be configured separately from incident data attributed.

D.

User attributes have been incorrectly mapped to Active Directory accounts.

Buy Now
Questions 5

Which two (2) actions are available for a “Network Prevent: Remove HTTP/HTTPS content” response rule when the content is unable to be removed? (Choose two.)

Options:

A.

Redirect the content to an alternative destination

B.

Block the content from being posted

C.

Encrypt the content before posting

D.

Remove the content through FlexResponse

E.

Allow the content to be posted

Buy Now
Questions 6

Which option correctly describes the two-tier installation type for Symantec DLP?

Options:

A.

Install the Oracle database on the host, and install the Enforce server and a detection server on a second host.

B.

Install the Oracle database on a local physical host, and install the Enforce server and detection servers on virtual hosts in the Cloud.

C.

Install the Oracle database and a detection server in the same host, and install the Enforce server on a second host.

D.

Install the Oracle database and Enforce server on the same host, and install detection servers on separate hosts.

Buy Now
Questions 7

Which statement accurately describes where Optical Character Recognition (OCR) On-Premises DLP Core components must be installed?

Options:

A.

The OCR engine must be installed directly on the Enforce server.

B.

The OCR engine must be installed on one or more detection servers.

C.

The OCR server software must by installed on one or more dedicated (non-detection) Windows servers.

D.

The OCR server software must be installed on one or more dedicated (non-detection) Linux servers.

Buy Now
Questions 8

Which type of detector integrates with Symantec CloudSOC?

Options:

A.

Cloud Detection Service for REST

B.

Cloud Detection Service for ICAP

C.

Cloud Detection Service for SMTP

D.

Cloud Prevent detector

Buy Now
Questions 9

A DLP administrator needs to stop the PacketCapture process on a detection server. Upon inspection of the Server Detail page, the administrator discovers that all processes are missing from the display.

What are the processes missing from the Server Detail page display?

Options:

A.

The detection server Display Control Process option is disabled on the Server Detail page.

B.

The Display Process Control setting on the Advanced Settings page is disabled.

C.

The detection server PacketCapture process is displayed on the Server Overview page.

D.

The Advanced Process Control setting on the System Settings page is deselected.

Buy Now
Questions 10

Refer to the exhibit. Which type of Endpoint response rule is shown?

250-587 Question 10

Options:

A.

Endpoint Prevent: User Notification

B.

Endpoint Prevent: Block

C.

Endpoint Prevent: Notify

D.

Endpoint Prevent: User Cancel

Buy Now
Questions 11

What is required on the Enforce server to communicate with the Symantec DLP database?

Options:

A.

Port 8082 should be opened

B.

CryptoMasterKey.properties file

C.

Symbolic links to .dbf files

D.

SQL*plus Client

Buy Now
Questions 12

Which detection method depends on “training sets”?

Options:

A.

Form Recognition

B.

Vector Machine Learning (VML)

C.

Index Document Matching (IDM)

D.

Exact Data Matching (IDM)

Buy Now
Questions 13

A divisional executive requests a report of all incidents generated by a particular region, summarized by department.

What does the DLP administrator need to configure to generate this report?

Options:

A.

Custom attributes

B.

Status attributes

C.

Sender attributes

D.

User attributes

Buy Now
Questions 14

Which server target uses the “Automated Incident Remediation Tracking” feature in Symantec DLP?

Options:

A.

File System High-Speed Discovery

B.

File System (standard)

C.

SharePoint

D.

Exchange

Buy Now
Questions 15

Where in the Enforce management console can a DLP administrator change the “UI.NO_SCAN.int” setting to disable the “Inspecting data” pop-up?

Options:

A.

Advanced Server Settings from the Endpoint Server Configuration

B.

Advanced Monitoring from the Agent Configuration

C.

Advanced Agent Settings from the Agent Configuration

D.

Application Monitoring from the Agent Configuration

Buy Now
Questions 16

Which two automated response rules will be active in policies that include Exact Data Matching (EDM) detection rule? (Choose two.)

Options:

A.

Endpoint Discover: Quarantine File

B.

All: Send Email Notification

C.

Endpoint Prevent: User Cancel

D.

Endpoint Prevent: Block

E.

Network Protect: Quarantine File

Buy Now
Questions 17

What is the correct order for data in motion when a customer has integrated their CloudSOC and DLP solutions?

Options:

A.

User > CloudSOC Gatelet > DLP Cloud Detection Service > Application

B.

User > Enforce > Application

C.

User > Enforce > CloudSOC > Application

D.

User > CloudSOC Gatelet > Enforce > Application

Buy Now
Questions 18

A DLP administrator has performed a test deployment of the DLP 15.0 Endpoint agent and now wants to uninstall the agent. However, the administrator no longer remembers the uninstall password.

What should the administrator do to work around the password problem?

Options:

A.

Apply a new global agent uninstall password in the Enforce management console.

B.

Manually delete all the Endpoint agent files from the test computer and install a new agent package.

C.

Replace the PGPsdk.dll file on the agent’s assigned Endpoint server with a copy from a different Endpoint server

D.

Use the UninstallPwdGenerator to create an UninstallPasswordKey.

Buy Now
Questions 19

A DLP administrator has added several approved endpoint devices as exceptions to an Endpoint Prevent policy that blocks the transfer of sensitive data. However, data transfers to these devices are still being blocked.

What is the first action an administrator should take to enable data transfers to the approved endpoint devices?

Options:

A.

Disable and re-enable the Endpoint Prevent policy to activate the changes

B.

Double-check that the correct device ID or class has been entered for each device

C.

Verify Application File Access Control (AFAC) is configured to monitor the specific application

D.

Edit the exception rule to ensure that the “Match On” option is set to “Attachments”

Buy Now
Questions 20

The Symantec Data Loss risk reduction approach has six stages.

Drag and drop the six correct risk reduction stages in the proper order of Occurrence column.

250-587 Question 20

Options:

Buy Now
Questions 21

Why would an administrator set the Similarity Threshold to s=zero when testing and tuning a Vector Machine Learning (VML) profile?

Options:

A.

To capture the matches to the Positive set

B.

To capture the matches to the negative set

C.

To see the false negatives only

D.

To see the entire range of potential matches

Buy Now
Questions 22

Which two factors are common sources of data leakage where the main actor is well-meaning insider? (Choose two.)

Options:

A.

An absence of a trained incident response team

B.

A disgruntled employee for a job with a competitor

C.

Merger and Acquisition activities

D.

Lack of training and awareness

E.

Broken business processes

Buy Now
Questions 23

Which option is an accurate use case for Information Centric Encryption (ICE)?

Options:

A.

The ICE utility encrypts files matching DLP policy being copied from network share through use of encryption keys.

B.

The ICE utility encrypts files matching DLP policy being copied to removable storage through use of encryption keys.

C.

The ICE utility encrypts files matching DLP policy being copied to removable storage on an endpoint use of certificates.

D.

The ICE utility encrypts files matching DLP policy being copied from network share through use of certificates

Buy Now
Questions 24

Which of the following is a good use case for Structured Data Identifiers (SDIs)?

Options:

A.

Detecting the copying of healthcare data in tabular format to USB devices from endpoint computers

B.

Detecting confidential financial data contained in XLSX or CSV email attachments

C.

Detecting partial sections of merger and acquisition documents in Network Discover scans

D.

Detecting single instances of Personally Identifiable Information (PII) in Endpoint Discover scans

Buy Now
Questions 25

An organization wants to restrict employees to copy files only a specific set of USB thumb drives owned by the organization.

Which detection method should the organization use to meet this requirement?

Options:

A.

Exact data Matching (EDM)

B.

Indexed Document matching (IDM)

C.

Described Content Matching (DCM)

D.

Vector Machine Learning (VML)

Buy Now
Questions 26

What should an administrator do if DLP policies are generating too many false positives?

Options:

A.

Ignore incident reports until a critical issue arises.

B.

Disable all policies temporarily.

C.

Allow users to approve exceptions manually.

D.

Refine detection methods, such as Exact Data Matching (EDM) and fingerprinting.

Buy Now
Questions 27

Why would an administrator set the Similarity Threshold to zero when testing and tuning a Vector Machine Learning (VML) profile?

Options:

A.

To capture the matches to the Negative set

B.

To capture the matches to the Positive set

C.

To see the entire range of potential matches

D.

To see the false negatives only

Buy Now
Questions 28

Where do you configure the list of Endpoint Servers (or load balancers) to which a DLP Agent can report?

Options:

A.

In the Agent Package

B.

In the Agent Configuration

C.

In the Agent Group

D.

In the Agent Overview

Buy Now
Questions 29

Which statement accurately describes where Optical Character Recognition (OCR) components must be installed?

Options:

A.

The OCR engine must be installed on detection server other than the Enforce server.

B.

The OCR server software must be installed on one or more dedicated (non-detection) Linux servers.

C.

The OCR engine must be directly on the Enforce server.

D.

The OCR server software must be installed on one or more dedicated (non-detection) Windows servers.

Buy Now
Questions 30

In the context of Network Discover scanning of Exchange servers, what is the Exchange Autodiscover service?

Options:

A.

It is a service on the Discover server that you enable to retrieve files from the Exchange server for detection analysis against your DLP policies.

B.

It is a service on the Exchange server that you enable to fetch Exchange server and mailbox information from Active Directory.

C.

It is a service on the Enforce server that you enable to resolve custom attributes in Network Discover incidents for Exchange servers.

D.

It is a service on the Exchange server that you enable to send files from the Exchange server for detection analysis against your DLP policies.

Buy Now
Questions 31

A DLP administrator created a new agent configuration for an Endpoint server. However, the endpoint agents fail to receive the new configuration.

What is one possible reason that the agent fails to receive the new configuration?

Options:

A.

The default agent configuration must be disabled before the new configuration can be assigned.

B.

The Endpoint server needs to be recycled so that the new agent configuration can take effect.

C.

The new agent configuration was saved but not applied to any endpoint groups.

D.

The new agent configuration was copied and modified from the default agent configuration.

Buy Now
Questions 32

Which two (2) detection technology options run ONLY on detection servers and NOT on endpoint agents? (Choose two.)

Options:

A.

Indexed Document Matching (IDM)

B.

Vector Machine Learning (VML)

C.

Described Content Matching (DCM)

D.

Exact Data Matching (EDM)

E.

Form Recognition

Buy Now
Exam Code: 250-587
Exam Name: Symantec Data Loss Prevention 16.x Administration Technical Specialist
Last Update: Aug 4, 2026
Questions: 108

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11